SentinelAI.NET is an open-source runtime security gateway for .NET AI apps and agents. It inspects prompts, retrieved content, model output and tool calls, enforces policy, and emits OpenTelemetry evidence.
Every request crosses four surfaces. Each is scanned, decided and recorded. Select a stage.
Each package exposes focused capabilities. Select a card for the contract and a sample.
Illustrative output of the v0.1 demo scenarios.
Add the middleware, then let security teams own the YAML. No redeploy to change a rule.
// register builder.Services.AddSentinelAI(o => { o.EnablePromptInjectionDetection(); o.EnablePiiProtection(); o.EnableToolAuthorization(); o.EnableOpenTelemetry(); }); // enforce app.UseSentinelAI();
security: promptInjection: action: block threshold: 0.85 pii: { action: redact } secrets: { action: block } toolCalls: delete_customer: action: require_confirmation
Strong tools already exist for detection, testing and observability. None combine .NET-native enforcement, a gateway and a tool firewall.
| Tool | Strength | What Sentinel adds |
|---|---|---|
| Promptfoo | Red teaming and CI testing | Production runtime enforcement |
| LlamaFirewall | Runtime scanners | Runs as a pluggable scanner behind policy |
| NeMo Guardrails | Input, output and tool rails | .NET-native, no Python service to run |
| Langfuse · OpenLLMetry | LLM observability | Security decisions on the same traces |
| YARP · Extensions.AI | Proxy and AI abstractions | Built on top of both |
Middleware, YARP, YAML policy, regex/PII/HTTP scanners, OTel events.
Per-tool authorization, argument validation, approval workflow.
PromptGuard, LlamaFirewall, Azure Content Safety, ONNX.
Optional Angular telemetry. Deliberately outside the MVP.
dotnet add package SentinelAI.AspNetCoreStar on GitHub ↗